logo

The Trojan Contact: Konni APT Hijacks KakaoTalk to Turn Victims into Attackers

ID: 5560f2ba-fd37-5b94-84fb-4adda7f09e04

STIX ID: report--5560f2ba-fd37-5b94-84fb-4adda7f09e04

Feed Name: securityonline.info

Threat Score
85/100

Date Published: 2026-03-19

Date Updated: 2026-04-23

Author: Ddos

...
...

Konni APT is conducting a sophisticated multi-stage campaign that begins with spear-phishing LNK files which execute PowerShell to deploy decoys and download AutoIt and multiple RATs (EndRAT, RftRAT, RemcosRAT), establishes persistence via a frequent scheduled task, and then abuses compromised KakaoTalk PC sessions to send malicious files to trusted contacts, enabling account-based secondary distribution and broader propagation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.